CVE Vulnerabilities

CVE-2012-4481

Published: May 02, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
4.3 LOW
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The safe-level feature in Ruby 1.8.7 allows context-dependent attackers to modify strings via the NameError#to_s method when operating on Ruby objects. NOTE: this issue is due to an incomplete fix for CVE-2011-1005.

Affected Software

NameVendorStart VersionEnd Version
RubyRuby-lang1.8.7 (including)1.8.7 (including)
Red Hat Enterprise Linux 5RedHatruby-0:1.8.5-27.el5*
Red Hat Enterprise Linux 6RedHatruby-0:1.8.7.352-10.el6_4*
Ruby1.8Ubuntuhardy*
Ruby1.8Ubuntulucid*
Ruby1.8Ubuntunatty*
Ruby1.8Ubuntuoneiric*
Ruby1.8Ubuntuprecise*
Ruby1.8Ubuntuquantal*
Ruby1.8Ubuntuupstream*
Ruby1.9Ubuntuhardy*

References